Major Characteristics : - Offline Encryption - Teslarvng Ransomware series - Automatically run ransomware by adding defragsrv service. - Adding "logg" in Task Scheduler to delete event log through run "C:\Windows\logg.bat" file for every 10 minutes. - Disable system restore (vssadmin.exe Delete Shadows /All /Quiet, wbadmin.exe delete catalog -quiet, WMIC.exe shadowcopy delete) - Utilizes SDelete from SysInternals to purge empty disc drive space, disabling possible recovery by file recovery tool. ("%Temp%\sdelete.exe" -nobanner -z <Drive Letter>:)